Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-0116

Published Jan 18, 2005

AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2005-0297

Published Jan 18, 2005

SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0221

Published Jan 17, 2005

Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0290

Published Jan 17, 2005

NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file ex…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0291

Published Jan 17, 2005

Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0292

Published Jan 17, 2005

Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0295

Published Jan 17, 2005

npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0296

Published Jan 17, 2005

NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0294

Published Jan 16, 2005

minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0094

Published Jan 15, 2005

Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (cras…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0095

Published Jan 15, 2005

The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0110

Published Jan 14, 2005

Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code v…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0113

Published Jan 14, 2005

inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0069

Published Jan 13, 2005

The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0111

Published Jan 13, 2005

Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0381

Published Jan 13, 2005

Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0740

Published Jan 13, 2005

The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0376

Published Jan 12, 2005

PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to refer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0456

Published Jan 12, 2005

Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0991

Published Jan 11, 2005

Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1039

Published Jan 11, 2005

The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0097

Published Jan 11, 2005

The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereferen…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0108

Published Jan 11, 2005

Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute l…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,676-4,700 of 4,932 CVEsPage 188 of 198